Spring Security's BCryptPasswordEncoder has a vulnerability identified as CVE-2025-22228, where it does not enforce maximum password length. This could potentially result in security risks for applications using this encoder for password encryption.

1m read timeFrom spring.io
Post cover image
Table of contents
DescriptionAffected Spring Products and VersionsMitigationCreditReferences

Sort: